Legal
Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how Jorora (“we”, “us”) processes personal data when you use our websites and the AI Freight Invoice Validator (the “Service”).
1. Controller
For users in Colombia and internationally, the data controller is the operator of Jorora as identified in the Service footer / account notices. Contact: the support email published in the product (or the email used for your account communications).
2. Data we process
- Account data: name, email, organization name, authentication metadata.
- Billing data: plan, credit balance, payment-provider customer/checkout identifiers (card data is handled by the payment processor; we do not store full card numbers).
- Documents you upload or ingest: carrier invoices, rate confirmations, PODs, BOLs, lumper receipts and extracted fields needed to run validations.
- Email intake metadata (when you enable email features): forwarding alias activity; if you connect Gmail, message metadata and PDF attachments we scan to propose invoice candidates (read-only access as authorized).
- Accounting handoff data (when you connect QuickBooks Online): OAuth tokens (encrypted at rest), company identifiers (e.g. realmId), and Bill/vendor fields you choose to push.
- Usage data: validations, decisions, rule outcomes, audit logs, technical logs.
- Device / site data: cookies or similar technologies as described in our Cookie Policy.
3. Purposes and legal bases
We process data to:
- Provide the Service and consume credits (contract / pre-contractual measures).
- Operate optional integrations you enable (Gmail intake, QuickBooks Bill handoff) under the same contract / legitimate interests, limited to the scopes you authorize.
- Secure accounts, prevent abuse, and debug failures (legitimate interests / legal duty).
- Comply with tax, accounting, and consumer obligations where applicable.
- Improve extraction quality using aggregated or de-identified signals where lawful.
If GDPR/UK GDPR or similar regimes apply to you, the legal bases are typically contract, legitimate interests, legal obligation, and consent where required (e.g. non-essential cookies or optional OAuth connections).
4. AI processing
Document fields may be processed by AI extraction providers (currently configured OpenAI models) solely to extract structured data for validation. Do not upload documents you are not authorized to process. See the AI Disclaimer.
4a. Business payment receipts (Colombia)
For Jorora Business (payment receipts, Nequi/Daviplata/bank screenshots or PDFs), we process files only to extract structured payment fields and export to your chosen Excel template. Receipts may contain transaction amounts, references, and counterparty labels — treat uploads as financial data. You can delete batches from your workspace Files area. We do not use your receipt images to train public AI models.
5. Beta integrations (selected customers)
Certain integrations — including Gmail inbox sync and QuickBooks Online Bill push — may be offered as Beta to selected customers only. Beta features may change, be limited by allowlist, or be withdrawn. You can disconnect OAuth connections at any time in the product (Settings → Integrations). Disconnecting stops new access; previously created QuickBooks Bills remain in your QuickBooks company.
6. Sharing
We share data with processors that help us operate the Service, such as:
- Hosting / database (e.g. Vercel, Neon/Postgres).
- Email delivery (e.g. Resend).
- Payments (e.g. Stripe and/or Polar, depending on configuration).
- AI extraction providers under contractual data processing terms.
- Google (Gmail API) when you connect a Google account for optional email intake — subject to Google’s terms and the scopes you approve.
- Intuit (QuickBooks Online) when you connect a QuickBooks company for optional accounting handoff — subject to Intuit’s terms and the scopes you approve.
We do not sell personal data.
7. International transfers
Infrastructure and processors may be located outside your country (including the United States). Where required, we rely on appropriate transfer mechanisms (e.g. SCCs) as implemented by those processors.
8. Retention
Account and billing records are kept while your account is active and as required by law. Uploaded documents and validation artifacts are retained to provide history according to your plan limits and operational needs, then deleted or anonymized according to our retention schedule. OAuth tokens are retained while a connection is active and removed or invalidated on disconnect. You may request deletion subject to legal holds.
9. Security
We use access controls, encrypted transport (TLS), tenant isolation by organization, encryption of third-party OAuth tokens at rest where applicable, and least-privilege practices. No method of transmission or storage is perfectly secure.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of personal data, and to object or withdraw consent. Colombian users may exercise habeas data rights under applicable Colombian data-protection rules. EU/EEA users may lodge a complaint with a supervisory authority. California residents may have CCPA/CPRA rights; Brazil residents may have LGPD rights. Contact us to exercise rights. You may also revoke Google or Intuit access from their respective account security settings.
11. Children
The Service is for business users and is not directed to children under 18.
12. Changes
We may update this Policy. Material changes will be posted with a new “Last updated” date.
These templates are provided for product launch readiness. They are not legal advice. Engage qualified counsel licensed in Colombia (and in any other jurisdiction where you market or sell) before relying on them commercially.
